Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A company uses Qualys to scan their internal network. The scan report shows a vulnerability with plugin output indicating that the server is running a version of Apache httpd vulnerable to CVE-2023-1234. The asset is a development web server that is not exposed to the internet. The CVSS score is 7.5 (High). However, the EPSS score is 0.001 (very low). Which of the following should be the primary factor in prioritizing this vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The asset is a development server not exposed to the internet, so remediation should be scheduled during normal maintenance.

Since the EPSS score is very low, the likelihood of exploitation in the wild is minimal. Additionally, the asset is not internet-facing, reducing exposure. The best approach is to consider the business context and asset criticality; development servers may be lower priority. However, among the options, the EPSS score is a strong indicator of exploitability. But given the low EPSS, the vulnerability might be deprioritized. The question asks for primary factor; business context (asset criticality and exposure) is key. But options include both EPSS and business context. The answer should be business context because the asset is internal and EPSS low, but business context might still prioritize if critical. However, in this scenario, the development server is likely not critical. The most appropriate is to consider the business context including asset criticality and exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The CVSS score of 7.5 indicates high severity, so it should be remediated immediately.

    Why it's wrong here

    While a CVSS score of 7.5 represents a high severity, relying solely on CVSS base scores ignores critical environmental and temporal metrics. Organizations must incorporate threat intelligence, such as the Exploit Prediction Scoring System (EPSS), and business context to prioritize patching effectively. Immediate remediation of non-critical, isolated assets based only on CVSS leads to inefficient resource allocation.

  • ✗

    The EPSS score of 0.001 indicates very low exploitability, so remediation can be delayed.

    Why it's wrong here

    Although an EPSS score of 0.001 suggests a low probability of exploitation in the wild, this metric is probabilistic and does not account for internal threat models. If the affected asset holds highly sensitive data or is critical to business continuity, relying blindly on low exploitability scores to delay patching could expose the organization to severe insider threats or lateral movement.

  • ✓

    The asset is a development server not exposed to the internet, so remediation should be scheduled during normal maintenance.

    Why this is correct

    This option correctly synthesizes business context and risk-based vulnerability management. Because the asset is a non-production development server isolated from the internet, the actual risk of exploitation is significantly mitigated. Combining this low exposure with a low EPSS score justifies scheduling the patch during routine maintenance windows rather than disrupting operations with an emergency deployment.

  • ✗

    The vulnerability is in Apache httpd, which is widely used, so it must be patched within 24 hours.

    Why it's wrong here

    The widespread deployment of software like Apache httpd increases its overall threat surface, but it does not dictate an automatic 24-hour SLA for every internal instance. Emergency patching cycles should be reserved for critical, internet-facing assets where active exploitation is occurring. Mandating immediate patching for isolated, non-production instances of common software creates unnecessary operational overhead and alert fatigue.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.